CWE-352 跨站请求伪造(CSRF) 类弱点 4918 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-352 跨站请求伪造是一种身份验证缺陷漏洞,指应用未能充分验证请求是否由用户主动发起。攻击者通常通过诱导用户点击恶意链接或加载隐蔽图片,利用用户已登录的会话状态,以用户身份执行非预期的操作,如转账或修改密码。开发者可通过在请求中添加并验证唯一的 CSRF 令牌、检查 Referer 头以及使用 SameSite Cookie 属性来有效防御此类攻击。
<form action="/url/profile.php" method="post"> <input type="text" name="firstname"/> <input type="text" name="lastname"/> <br/> <input type="text" name="email"/> <input type="submit" name="submit" value="Update"/> </form>// initiate the session in order to validate sessions session_start(); //if the session is registered to a valid user then allow update if (! session_is_registered("username")) { echo "invalid session detected!"; // Redirect user to login page [...] exit; } // The user session is valid, so process the request // and update the information update_profile(); function update_profile { // read in the data from $POST and send an update // to the database SendUpdateToDatabase($_SESSION['username'], $_POST['email']); [...] echo "Your profile has been successfully updated."; }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2018-0446 | Cisco Industrial Network Director 跨站请求伪造漏洞 — Cisco Industrial Network Director | 8.8 | - | 2018-10-05 |
| CVE-2018-0451 | Cisco Tetration Analytics 跨站请求伪造漏洞 — Cisco Tetration Analytics | 8.0 | - | 2018-10-05 |
| CVE-2018-15401 | Cisco Hosted Collaboration Mediation Fulfillment 跨站请求伪造漏洞 — Cisco Hosted Collaboration Mediation Fulfillment | 8.8 | - | 2018-10-05 |
| CVE-2018-8844 | Philips e-Alert 跨站请求伪造漏洞 — e-Alert Unit (non-medical device) | 8.8 | - | 2018-09-26 |
| CVE-2018-15612 | Avaya Aura Orchestration Designer Runtime Config组件跨站请求伪造漏洞 — Orchestration Designer | 8.8 | - | 2018-09-21 |
| CVE-2016-7067 | Tildeslash Monit Service Manager 跨站请求伪造漏洞 — monit | 7.1 | - | 2018-09-10 |
| CVE-2018-10884 | Ansible Tower 跨站请求伪造漏洞 — ansible-tower | 8.8 | - | 2018-08-22 |
| CVE-2018-14783 | NetComm Wireless G LTE Light Industrial M2M Router(NWL-25)跨站请求伪造漏洞 — NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. | 8.8 | - | 2018-08-10 |
| CVE-2018-0413 | Cisco Identity Services Engine 跨站请求伪造漏洞 — Cisco Identity Services Engine unknown | 8.8 | - | 2018-08-01 |
| CVE-2017-3187 | dotCMS 跨站请求伪造漏洞 — Administration Panel | 8.8 | - | 2018-07-24 |
| CVE-2016-6557 | ASUS RP-AC52 Access Point 跨站请求伪造漏洞 — RP-AC52 Access Point | 8.0 | - | 2018-07-13 |
| CVE-2016-6578 | CodeLathe FileCloud 跨站请求伪造漏洞 — FileCloud | 8.8 | - | 2018-07-13 |
| CVE-2018-12540 | Eclipse Vert.x 跨站请求伪造漏洞 — Eclipse Vert.x | 8.8 | - | 2018-07-12 |
| CVE-2018-10895 | qutebrowser 跨站请求伪造漏洞 — cross-site request forgery flaw allows sites to access 'qute | 8.8 | - | 2018-07-12 |
| CVE-2016-10522 | rails_admin ruby 跨站请求伪造漏洞 — rails_admin ruby gem | 8.8 | - | 2018-07-05 |
| CVE-2018-11448 | Siemens SCALANCE M875 跨站脚本漏洞 — SCALANCE M875 | 4.8 | - | 2018-06-26 |
| CVE-2018-0363 | Cisco Unified Communications Manager IM & Presence Service 跨站请求伪造漏洞 — Cisco Unified Communications Manager IM & Presence Service unknown | 8.8 | - | 2018-06-21 |
| CVE-2018-0364 | Cisco Unified Communications Domain Manager 跨站请求伪造漏洞 — Cisco Unified Communications Domain Manager unknown | 8.8 | - | 2018-06-21 |
| CVE-2018-0365 | Cisco Firepower Management Center 跨站请求伪造漏洞 — Cisco Firepower Management Center unknown | 8.8 | - | 2018-06-21 |
| CVE-2014-0594 | Open Build Service 安全漏洞 — Open Build Service | 8.8 | - | 2018-06-08 |
| CVE-2017-7906 | ABB IP GATEWA 跨站请求伪造漏洞 — ABB IP GATEWAY | 8.8 | - | 2018-06-06 |
| CVE-2016-10529 | Droppy 安全漏洞 — droppy node module | 8.3 | - | 2018-05-31 |
| CVE-2017-9641 | OSIsoft PI Coresight 跨站请求伪造漏洞 — PI Coresight | 8.8 | - | 2018-05-25 |
| CVE-2018-0270 | Cisco IoT Field Network Director 跨站请求伪造漏洞 — Cisco IoT Field Network Director | 8.8 | - | 2018-05-17 |
| CVE-2018-0255 | 多款Cisco Industrial Ethernet交换机跨站请求伪造漏洞 — Cisco Industrial Ethernet Switches | 8.8 | - | 2018-04-19 |
| CVE-2018-0259 | Cisco MATE Collector 跨站请求伪造漏洞 — Cisco MATE Collector | 8.8 | - | 2018-04-19 |
| CVE-2018-1098 | etcd 跨站请求伪造漏洞 — etcd | 8.8 | - | 2018-04-03 |
| CVE-2018-7524 | Geutebrück G-Cam/EFD-2250和Topline TopFD-2125 跨站请求伪造漏洞 — Geutebrück G-Cam/EFD-2250 (part n° 5.02024) firmware and Topline TopFD-2125 (part n° 5.02820) firmware | 8.8 | - | 2018-03-22 |
| CVE-2017-0933 | Ubiquiti Networks EdgeOS 跨站请求伪造漏洞 — EdgeRouter X | 8.0 | - | 2018-03-22 |
| CVE-2018-1230 | Pivotal Spring Batch Admin 跨站请求伪造漏洞 — Spring Batch Admin | 8.8 | - | 2018-03-21 |
CWE-352(跨站请求伪造(CSRF)) 是常见的弱点类别,本平台收录该类弱点关联的 4918 条 CVE 漏洞。